CVE-2022-36537 is an information disclosure vulnerability in the ZK Framework affecting versions 8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1, and 9.6.1. The flaw is exposed through the AuUploader component, which can be targeted with a crafted POST request to obtain sensitive information. In environments where the vulnerable ZK Framework is embedded in downstream products, the issue may also contribute to more severe outcomes depending on product-specific integration and exposed functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a fully operational exploit for CVE-2022-36537, targeting the ZK Framework and products using it, such as ConnectWise Recover and R1Soft Server Backup Manager. The main exploit script (CVE-2022-36537.py) is written in Python and automates the process of exploiting an authentication bypass in the ZK framework. It allows an attacker to read arbitrary files from the server and to deploy a malicious JDBC driver (compiled from Driver.java) as a backdoor. The Java payload, when loaded by the target, executes arbitrary system commands: on Linux, it opens a reverse shell to 192.168.1.3:2022; on Windows, it launches the calculator as a demonstration. The exploit is operational and requires the attacker to supply a target URL and, optionally, a file to read or to deploy the backdoor. The repository includes all necessary code, a requirements.txt for dependencies, and a README with usage instructions and affected versions. The attack is performed over HTTP(S) endpoints exposed by the vulnerable server, specifically targeting /zkau/upload and /login.zul. The exploit demonstrates both file read and remote code execution capabilities, making it a significant threat to unpatched systems.
This repository provides a working exploit for CVE-2022-36537, targeting the ZK Framework and products using it, such as ConnectWise R1Soft Server Backup Manager. The main exploit script (CVE-2022-36537.py) is written in Python and automates the process of exploiting an authentication bypass in the ZK framework's /zkau/upload endpoint. The exploit allows an unauthenticated attacker to read arbitrary files from the server and, more critically, to upload a malicious JDBC driver (compiled from Driver.java) as a backdoor. The Java payload, when loaded by the target, executes a reverse shell to a hardcoded IP (192.168.1.3:2022) on Linux or launches calc.exe on Windows, demonstrating remote code execution. The repository includes all necessary code to build the payload, exploit the vulnerability, and provides clear instructions in the README. The exploit is operational and can be used to achieve RCE on vulnerable systems. The endpoints /zkau/upload and /login.zul are key to the attack, and the payload is customizable by modifying the Java code. The repository is well-structured, with clear separation between exploit logic (Python) and payload (Java). No evidence of fake or detection-only code was found.
This repository provides a working exploit for CVE-2022-36537, targeting the ZK Framework and products using it, such as ConnectWise R1Soft Server Backup Manager and ConnectWise Recover. The main exploit script (CVE-2022-36537.py) is written in Python and automates the process of exploiting an authentication bypass in the ZK framework. It allows an attacker to read arbitrary files from the server and to achieve remote code execution by uploading a malicious JDBC driver (compiled from Driver.java). The Java payload (Driver.java) is a backdoored MySQL JDBC driver that, when loaded by the target, executes a reverse shell to 192.168.1.3:2022 (Linux) or launches calc.exe (Windows). The exploit interacts with endpoints such as /zkau/upload and /login.zul to perform the attack. The repository also includes a requirements.txt for dependencies and a README.md with background and usage instructions. The exploit is operational, providing both file read and code execution capabilities, and is not just a proof of concept.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.